Remote Β· worldwide, UTC+4 acceptedSalary not disclosedfull-timeVerified 1w agoHimalayas
You will be UserGems' single dedicated security person, taking over the operational majority of the security work the Sr. Director currently owns.
Responsibilities
Own SOC 2 - keep Drata green and audits clean.
Lead ISO 27001 implementation, then ISO 42001.
Run the customer security questionnaire process (SafeBase + Trust Center) - fast turnaround directly unblocks revenue.
Drata-driven AWS remediation. Action simple Drata findings directly in AWS yourself - IAM tweaks, S3 settings, secrets hygiene, audit-trail follow-ups. Larger or higher-risk changes go to engineering.
Vulnerability management.
Oversee and extend the existing scanner-findings automation in Linear; hit SLAs.
Light secure code review. Spot-check high-risk features and new repositories (especially AI/LLM systems) before they go to production; escalate deeper AppSec questions to engineering and external pen testers.
Threat detection & response. Tune GuardDuty findings, evaluate central logging / SIEM options, run tabletop exercises, mature the IRP from written to rehearsed.
Offensive security. Run the annual external pen test, perform regular internal pen tests yourself, handle external researcher reports and bug bounty payouts.